Bea Weblogic Server vulnerabilities
146 known vulnerabilities affecting bea/weblogic_server.
Total CVEs
146
CISA KEV
0
Public exploits
11
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH31MEDIUM92LOW16
Vulnerabilities
Page 7 of 8
CVE-2003-1223MEDIUMCVSS 5.0v6.1v7.0+2 more2003-12-31
CVE-2003-1223 [MEDIUM] CVE-2003-1223: The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to
The Node Manager for BEA WebLogic Express and Server 6.1 through 8.1 SP 1 allows remote attackers to cause a denial of service (Node Manager crash) via malformed data to the Node Manager's port, as demonstrated by nmap.
nvd
CVE-2003-1226LOWCVSS 2.1v7.0v7.0.0.12003-12-31
CVE-2003-1226 [LOW] CVE-2003-1226: BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryptio
BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores certain secrets concerning password encryption insecurely in config.xml, filerealm.properties, and weblogic-rar.xml, which allows local users to learn those secrets and decrypt passwords.
nvd
CVE-2003-1224LOWCVSS 2.1v7.0v7.0.0.12003-12-31
CVE-2003-1224 [LOW] CVE-2003-1224: Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRu
Weblogic.admin for BEA WebLogic Server and Express 7.0 and 7.0.0.1 displays the JDBCConnectionPoolRuntimeMBean password to the screen in cleartext, which allows attackers to read a user's password by physically observing ("shoulder surfing") the screen.
nvd
CVE-2003-1225LOWCVSS 2.1v7.0v7.0.0.12003-12-31
CVE-2003-1225 [LOW] CVE-2003-1225: The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in
The default CredentialMapper for BEA WebLogic Server and Express 7.0 and 7.0.0.1 stores passwords in cleartext on disk, which allows local users to extract passwords.
nvd
CVE-2003-1437LOWCVSS 2.1v7.0v7.0.0.12003-12-31
CVE-2003-1437 [LOW] CVE-2003-1437: BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keyst
BEA WebLogic Express and WebLogic Server 7.0 and 7.0.0.1, stores passwords in plaintext when a keystore is used to store a private key or trust certificate authorities, which allows local users to gain access.
nvd
CVE-2003-0623MEDIUMCVSS 4.3v4.2v5.0.1+1 more2003-12-01
CVE-2003-0623 [MEDIUM] CVE-2003-0623: Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlie
Cross-site scripting (XSS) vulnerability in the Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to inject arbitrary web script via the INIFILE argument.
nvd
CVE-2003-0621MEDIUMCVSS 5.0PoCv4.2v5.0.1+1 more2003-12-01
CVE-2003-0621 [MEDIUM] CVE-2003-0621: The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the e
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files outside the web root via modified paths in the INIFILE argument.
nvd
CVE-2003-0622MEDIUMCVSS 5.0v4.2v5.0.1+1 more2003-12-01
CVE-2003-0622 [MEDIUM] CVE-2003-0622: The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to cause a denial of service (hang) via pathname arguments that contain MS-DOS device names such as CON and AUX.
nvd
CVE-2003-0624MEDIUMCVSS 4.3PoC≤ 8.1v3.1.82003-12-01
CVE-2003-0624 [MEDIUM] CWE-79 CVE-2003-0624: Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier al
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attackers to inject malicious web script via the person parameter.
nvd
CVE-2003-0733MEDIUMCVSS 6.8v5.1v7.02003-10-20
CVE-2003-0733 [MEDIUM] CVE-2003-0733: Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data
Multiple cross-site scripting (XSS) vulnerabilities in WebLogic Integration 7.0 and 2.0, Liquid Data 1.1, and WebLogic Server and Express 5.1 through 7.0, allow remote attackers to execute arbitrary web script and steal authentication credentials via (1) a forward instruction to the Servlet container or (2) other vulnerabilities in the WebLogic Server console
nvd
CVE-2003-0151HIGHCVSS 7.5v6.0v6.1+2 more2003-03-24
CVE-2003-0151 [HIGH] CVE-2003-0151: BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain interna
BEA WebLogic Server and Express 6.0 through 7.0 does not properly restrict access to certain internal servlets that perform administrative functions, which allows remote attackers to read arbitrary files or execute arbitrary code.
nvd
CVE-2003-1095MEDIUMCVSS 4.6v7.0v7.0.0.12003-03-18
CVE-2003-1095 [MEDIUM] CVE-2003-1095: BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web app
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when using "memory" session persistence for web applications, does not clear authentication information when a web application is redeployed, which could allow users of that application to gain access without having to re-authenticate.
nvd
CVE-2002-2141HIGHCVSS 7.5v7.0v7.0.0.12002-12-31
CVE-2002-2141 [HIGH] CVE-2002-2141: BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB
BEA WebLogic Server and Express 7.0 and 7.0.0.1, when running Servlets and Enterprise JavaBeans (EJB) on more than one server, will remove the security constraints and roles on all servers for any Servlets or EJB that are used by an application that is undeployed on one server, which could allow remote attackers to conduct unauthorized activities in violation o
nvd
CVE-2002-2142HIGHCVSS 7.5v6.0v6.1+2 more2002-12-31
CVE-2002-2142 [HIGH] CVE-2002-2142: An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading
An undocumented extension for the Servlet mappings in the Servlet 2.3 specification, when upgrading to WebLogic Server and Express 7.0 Service Pack 1 from BEA WebLogic Server and Express 6.0 through 7.0.0.1, does not prepend a "/" character in certain URL patterns, which prevents the proper enforcement of role mappings and policies in applications that use the e
nvd
CVE-2002-2177LOWCVSS 2.6v6.1v7.0+1 more2002-12-31
CVE-2002-2177 [LOW] CVE-2002-2177: BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BE
BEA WebLogic Server and Express 6.1 through 7.0.0.1 buffers HTTP requests in a way that can cause BEA to send the same response for two different HTTP requests, which could allow remote attackers to obtain sensitive information that was intended for other users.
nvd
CVE-2002-1030LOWCVSS 2.6v5.1v6.0+2 more2002-10-04
CVE-2002-1030 [LOW] CVE-2002-1030: Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 al
Race condition in Performance Pack in BEA WebLogic Server and Express 5.1.x, 6.0.x, 6.1.x and 7.0 allows remote attackers to cause a denial of service (crash) via a flood of data and connections.
nvd
CVE-2002-0106MEDIUMCVSS 5.0PoCv6.12002-03-25
CVE-2002-0106 [MEDIUM] CVE-2002-0106: BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.
nvd
CVE-2001-0098CRITICALCVSS 10.0PoC≤ 4.5.22001-02-12
CVE-2001-0098 [CRITICAL] CVE-2001-0098: Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary com
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.
nvd
CVE-2000-1238HIGHCVSS 7.5v5.12000-12-31
CVE-2000-1238 [HIGH] CVE-2000-1238: BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass acces
BEA Systems WebLogic Express and WebLogic Server 5.1 SP1-SP6 allows remote attackers to bypass access controls for restricted JSP or servlet pages via a URL with multiple / (forward slash) characters before the restricted pages.
nvd
CVE-2000-0684CRITICALCVSS 10.0PoCv3.1.8v4.0.4+1 more2000-10-20
CVE-2000-0684 [CRITICAL] CVE-2000-0684: BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote att
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile and execute Java JSP code by directly invoking the servlet on any source file.
nvd